CVE-2023-33982
24.05.2023, 18:15
Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can decrypt network traffic between two accounts if they later compromise both accounts. NOTE: the eavesdropping is typically impractical because BHP runs over an encrypted session that uses the Tor hidden service protocol.Enginsight
Vendor | Product | Version |
---|---|---|
briarproject | briar | 𝑥 < 1.5.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References